CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,672 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
169,085 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2010-3886 EXP | The CTimeoutEventList::InsertIntoTimeoutList function in Microsoft mshtml.dll uses a certain pointer value as part of producing Timer ID values for th… | Patch early | 4.3 medium | 16.5% | 2010-10-08 |
| CVE-2003-0009 EXP | Cross-site scripting (XSS) vulnerability in Help and Support Center for Microsoft Windows Me allows remote attackers to execute arbitrary script in th… | Patch early | 6.8 medium | 16.5% | 2003-03-07 |
| CVE-2006-2661 EXP | ftutil.c in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a crafted font file that triggers a null dereference. | Patch early | 5.0 medium | 16.5% | 2006-05-30 |
| CVE-2006-4889 EXP | Multiple PHP remote file inclusion vulnerabilities in Telekorn SignKorn Guestbook (SL) 1.3 and earlier, when register_globals is enabled, allow remote… | Patch early | 5.1 medium | 16.4% | 2006-09-19 |
| CVE-2021-25161 EXP | A remote cross-site scripting (xss) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x:… | Patch early | 6.1 medium | 16.4% | 2021-03-30 |
| CVE-2007-4890 EXP | Absolute directory traversal vulnerability in a certain ActiveX control in the VB To VSI Support Library (VBTOVSI.DLL) 1.0.0.0 in Microsoft Visual Stu… | Patch early | 5.8 medium | 16.4% | 2007-09-14 |
| CVE-2010-1532 EXP | Directory traversal vulnerability in the givesight PowerMail Pro (com_powermail) component 1.5.3 for Joomla! allows remote attackers to read arbitrary… | Patch early | 5.0 medium | 16.3% | 2010-04-26 |
| CVE-2009-1217 EXP | Off-by-one error in the GpFont::SetData function in gdiplus.dll in Microsoft GDI+ on Windows XP allows remote attackers to cause a denial of service (… | Patch early | 4.3 medium | 16.3% | 2009-04-01 |
| CVE-2005-4717 EXP | Microsoft Internet Explorer 6.0 on Windows NT 4.0 SP6a, Windows 2000 SP4, Windows XP SP1, Windows XP SP2, and Windows Server 2003 SP1 allows remote at… | Patch early | 5.0 medium | 16.3% | 2005-12-31 |
| CVE-2015-5065 EXP | Absolute path traversal vulnerability in proxy.php in the google currency lookup in the Paypal Currency Converter Basic For WooCommerce plugin before… | Patch early | 5.0 medium | 16.3% | 2015-06-24 |
| CVE-2000-0580 EXP | Windows 2000 Server allows remote attackers to cause a denial of service by sending a continuous stream of binary zeros to various TCP and UDP ports,… | Patch early | 5.0 medium | 16.3% | 2000-06-30 |
| CVE-2008-2005 EXP | The SuiteLink Service (aka slssvc.exe) in WonderWare SuiteLink before 2.0 Patch 01, as used in WonderWare InTouch 8.0, allows remote attackers to caus… | Patch early | 5.0 medium | 16.3% | 2008-05-06 |
| CVE-2013-3166 EXP | Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 16.3% | 2013-07-10 |
| CVE-2007-2718 EXP | Cross-site scripting (XSS) vulnerability in the WebMail system in Stalker CommuniGate Pro 5.1.8 and earlier, when using Microsoft Internet Explorer, a… | Patch early | 4.3 medium | 16.3% | 2007-05-16 |
| CVE-2006-0911 EXP | NmService.exe in Ipswitch WhatsUp Professional 2006 allows remote attackers to cause a denial of service (CPU consumption) via crafted requests to Log… | Patch early | 5.0 medium | 16.3% | 2006-02-28 |
| CVE-2009-4019 EXP | mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of certain SELECT statements with sub… | Patch early | 4.0 medium | 16.3% | 2009-11-30 |
| CVE-2015-4666 EXP | Directory traversal vulnerability in opm/read_sessionlog.php in Xceedium Xsuite 2.4.4.5 and earlier allows remote attackers to read arbitrary files vi… | Patch early | 5.0 medium | 16.2% | 2015-08-13 |
| CVE-2004-0474 EXP | Help Center (HelpCtr.exe) may allow remote attackers to read or execute arbitrary files via an "http://" or "file://" argument to the topic parameter… | Patch early | 5.1 medium | 16.2% | 2004-07-07 |
| CVE-2000-1058 EXP | Buffer overflow in OverView5 CGI program in HP OpenView Network Node Manager (NNM) 6.1 and earlier allows remote attackers to cause a denial of servic… | Patch early | 5.0 medium | 16.2% | 2000-12-11 |
| CVE-2017-10355 EXP | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected a… | Patch early | 5.3 medium | 16.2% | 2017-10-19 |
| CVE-2006-4384 EXP | Heap-based buffer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via the COLOR_64 chunk in a… | Patch early | 5.1 medium | 16.2% | 2006-09-12 |
| CVE-2018-11412 EXP | In the Linux kernel 4.13 through 4.16.11, ext4_read_inline_data() in fs/ext4/inline.c performs a memcpy with an untrusted length value in certain circ… | Patch early | 5.9 medium | 16.2% | 2018-05-24 |
| CVE-2013-1603 EXP | An Authentication vulnerability exists in D-LINK WCS-1100 1.02, TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_TESCO, DCS-7510 1.00, DCS-7410 1.00, DC… | Patch early | 5.3 medium | 16.1% | 2020-01-28 |
| CVE-2009-1872 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Adobe ColdFusion Server 8.0.1, 8, and earlier allow remote attackers to inject arbitrary web sc… | Patch early | 4.3 medium | 16.1% | 2009-08-18 |
| CVE-2021-24276 EXP | The Contact Form by Supsystic WordPress plugin before 1.7.15 did not sanitise the tab parameter of its options page before outputting it in an attribu… | Patch early | 6.1 medium | 16% | 2021-05-05 |
| CVE-2017-14016 EXP | A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. The application lacks proper validation of… | Patch early | 6.3 medium | 16% | 2017-11-06 |
| CVE-2004-2090 EXP | Microsoft Internet Explorer 5.0.1 through 6.0 allows remote attackers to determine the existence of arbitrary files via the VBScript LoadPicture metho… | Patch early | 5.0 medium | 16% | 2004-02-07 |
| CVE-2010-1658 EXP | Directory traversal vulnerability in the Code-Garage NoticeBoard (com_noticeboard) component 1.3 for Joomla! allows remote attackers to read arbitrary… | Patch early | 5.0 medium | 16% | 2010-05-03 |
| CVE-2020-28351 EXP | The conferencing component on Mitel ShoreTel 19.46.1802.0 devices could allow an unauthenticated attacker to conduct a reflected cross-site scripting… | Patch early | 6.1 medium | 16% | 2020-11-09 |
| CVE-2024-8945 EXP | A vulnerability has been found in CodeCanyon RISE Ultimate Project Manager 3.7.0 and classified as critical. This vulnerability affects unknown code o… | Patch early | 5.5 medium | 16% | 2024-09-17 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt